Skip to content

Commit 733a506

Browse files
committed
Timeline - Noa
1 parent b6fe2b9 commit 733a506

9 files changed

+33
-14
lines changed

defender-xdr/advanced-hunting-query-results.md

Lines changed: 33 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -32,10 +32,11 @@ appliesto:
3232

3333
While you can construct your [advanced hunting](advanced-hunting-overview.md) queries to return precise information, you can also work with the query results to gain further insight and investigate specific activities and indicators. You can take the following actions on your query results:
3434

35-
- View results as a table or chart
36-
- Export tables and charts
37-
- Drill down to detailed entity information
38-
- Tweak your queries directly from the results
35+
- [View results as a table or chart](#view-query-results-as-a-table-or-chart)
36+
- [Export tables and charts](#export-tables-and-charts)
37+
- [Drill down to detailed entity information](#drill-down-from-query-results)
38+
- [Tweak your queries directly from the results](#tweak-your-queries-from-the-results)
39+
- [View timeline of events](#automatic-timeline-rendering)
3940

4041
## View query results as a table or chart
4142

@@ -202,44 +203,62 @@ By default, a timeline appears above the advanced hunting results that displays
202203

203204
:::image type="content" source="/defender/media/advanced-hunting-query-results-timeline.png" alt-text="Screenshot of the timeline above the query results in advanced hunting." lightbox="/defender/media/advanced-hunting-query-results-timeline.png":::
204205

205-
You can select whether or not the timeline is displayed by default in the **Page preferences** settings.
206+
You can select whether or not the timeline is displayed by default in the **Chart preferences** settings.
206207

207-
:::image type="content" source="/defender/media/advanced-hunting-page-preferences.png" alt-text="Screenshot of the Page preferences settings in advanced hunting." lightbox="/defender/media/advanced-hunting-page-preferences-zoom.png":::
208+
:::image type="content" source="/defender/media/advanced-hunting-chart-preferences.png" alt-text="Screenshot of the Page preferences settings in advanced hunting." lightbox="/defender/media/advanced-hunting-chart-preferences.png":::
208209

209-
The timeline automatically adjusts its resolution based on the range of results. You can click any point on the timeline to filter both the results and the timeline to that specific time range. The timeline also updates its scale to match the selected time period, so when you filter by a specific range, it zooms in to show event distribution in high resolution.
210+
The timeline automatically adjusts its resolution based on the range of results.
210211

211-
The timeline only appears if there are more than 40 events in your results and there's `Timestamp` or `timeGenerated` column.
212+
### Filter the timeline results
212213

213-
### [Unfiltered timeline](#tab/unfiltered)
214+
Select any point on the timeline to filter both the results and the timeline to that specific time range. The timeline also updates its scale to match the selected time period, so when you filter by a specific range, it zooms in to show event distribution in high resolution.
215+
216+
#### [Unfiltered timeline](#tab/unfiltered)
214217

215218
The following screenshot shows the results of a query that returns 1,000 email events. The timeline is unfiltered, so it displays the full range of results with a timestamp for each day. Select a day or range of days to filter the results for that time period.
216219

217220
:::image type="content" source="/defender/media/advanced-hunting-unfiltered-results.png" alt-text="Screenshot of an advanced hunting query of 1,000 email events with all the results unfiltered." lightbox="/defender/media/advanced-hunting-unfiltered-results.png":::
218221

219-
### [Filtered timeline](#tab/filtered)
222+
#### [Filtered timeline](#tab/filtered)
220223

221224
The following screenshot shows the zoomed in results of a query filtered to a specific date.
222225

223226
:::image type="content" source="/defender/media/advanced-hunting-filtered-results.png" alt-text="Screenshot of an advanced hunting query of 1,000 email events with the results filtered to a specific date." lightbox="/defender/media/advanced-hunting-filtered-results.png":::
224227

225228
---
226229

227-
You can group the results in the timeline by any column that has at least two but less than 50 unique values.
230+
### Split the timeline by values
231+
232+
You can split the results in the timeline by any column that has at least two but less than 50 unique values.
228233

229-
### [Ungrouped timeline](#tab/ungrouped)
234+
#### [Ungrouped timeline](#tab/ungrouped)
230235

231236
The following screenshot shows the results of a query that returns 1,000 email events. The timeline is ungrouped, so it displays all the results in a single line.
232237

233238
:::image type="content" source="/defender/media/advanced-hunting-ungrouped.png" alt-text="Screenshot of an advanced hunting query of 1,000 email events with the results all together in one line." lightbox="/defender/media/advanced-hunting-ungrouped.png":::
234239

235-
### [Grouped timeline](#tab/grouped)
240+
#### [Grouped timeline](#tab/grouped)
236241

237242
The following screenshot shows the results grouped by last email action with a separate line for each action.
238243

239-
:::image type="content" source="/defender/media/advanced-hunting-grouped.png" alt-text="Screenshot of an advanced hunting query of 1,000 email events with the results grouped by last email action." lightbox="/defender/media/advanced-hunting-grouped-zoom.png":::
244+
:::image type="content" source="/defender/media/advanced-hunting-grouped.png" alt-text="Screenshot of an advanced hunting query of 1,000 email events with the results grouped by last email action." lightbox="/defender/media/advanced-hunting-grouped.png":::
240245

241246
---
242247

248+
### Change chart type
249+
250+
You can change the chart type of the timeline by selecting a different option from the chart type dropdown menu. The available chart types include:
251+
252+
- Column chart
253+
- Pie chart
254+
255+
### Rendering conditions
256+
257+
The timeline only appears if the following conditions are met:
258+
259+
- There are more than 40 events in your results.
260+
- There's `Timestamp` or `timeGenerated` column.
261+
243262
## Related topics
244263

245264
- [Advanced hunting overview](advanced-hunting-overview.md)
97 KB
Loading
35.2 KB
Loading
-161 KB
Binary file not shown.
-141 KB
Loading
-29.7 KB
Binary file not shown.
-109 KB
Loading
-109 KB
Loading
-117 KB
Loading

0 commit comments

Comments
 (0)